Partitioned Vehicle ECU for Safe Third-Party App Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Vehicle manufacturers face challenges in seamlessly integrating third-party applications into vehicles, ensuring compatibility, safety, security, and maintaining a consistent user experience while adhering to stringent safety and regulatory standards.
Innovation Solution
A custom application system for safe vehicle operation is implemented, utilizing a single electronic control unit (ECU) that includes a safety processor and an application processor partitioned to ensure safe operation and execution of applications. The safety processor maintains a safe operating envelope by arbitrating requests from the application processor, ensuring compliance with safety standards like ASIL-D.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple electronic control units are used to execute applications and control vehicle subsystems, then application functionality and programmability are improved, but system complexity and integration difficulty increase
Solution Approach 1:
The patent merges the application execution function and vehicle control function into a single electronic control unit. The ECU includes a processor that can both execute applications and control vehicle subsystems, eliminating the need for multiple separate control units and reducing system integration complexity.
Solution Approach 2:
The electronic control unit is designed with multi-functionality, where a single processor can dynamically switch between executing various applications and controlling different vehicle subsystems. This universal design allows one ECU to perform multiple roles that traditionally required separate dedicated control units.
2Adaptability or versatility
If applications are integrated into the vehicle's control system, then user experience and functionality are improved, but safety risks and security vulnerabilities increase
Solution Approach 1:
The patent segments the processor's operation into distinct modes: application execution mode and vehicle control mode. The processor dynamically switches between these modes, ensuring that applications run in isolated contexts while vehicle control functions maintain priority access and adherence to safety standards. This segmentation allows both application functionality and safety to coexist.
Solution Approach 2:
The system employs dynamic mode switching where the processor adapts its behavior based on operational context. When vehicle control is required, the processor prioritizes safety-critical functions; when safe, it executes applications. This dynamic approach allows the system to balance user experience enhancements with safety requirements.
3Device complexity
If a single electronic control unit executes both applications and controls vehicle subsystems, then device complexity is reduced, but the risk of application interference with safe operation increases
Solution Approach 1:
The processor is segmented into distinct operational contexts through mode switching. During application execution mode, applications run with limited access to vehicle control functions. During vehicle control mode, the processor exclusively handles safety-critical operations. This temporal and functional segmentation prevents application interference with safe operation while maintaining a single integrated ECU.
Solution Approach 2:
The processor acts as an intermediary that mediates between applications and vehicle subsystems. It selectively gates access to control functions, allowing applications to request operations only when it is safe to do so and when they comply with safety standards. This intermediary role prevents harmful interference while enabling application functionality.
Data Source
AI summary
A custom application system for safe vehicle operation is described. In one or more implementations, a single electronic control unit (ECU) of a vehicle controls safe operation of the vehicle and also executes applications, e.g., third party applications, within a partition that isolates execution of the applications from components responsible for the vehicle's safe operation. In accordance with the described techniques, the ECU includes a first processor to execute the applications and a second processor to maintain an operating state of the vehicle within a safe operating envelope of the vehicle. The second processor receives requests from the applications executed by the first processor and arbitrates them based on satisfying safety rules for the vehicle.


